Understanding Roles & Permissions
Director, Manager, Member, Viewer — plus Team Plus+ field RBAC on billing, keys, agents, and knowledge.
FuseIQ uses a 4-tier role system to control what each team member can see and do. Roles are assigned when you invite a user and can be changed later by Directors. On Team Plus+, additional field-level gates protect sensitive resources (billing, API keys, branding, SSO, agent system prompts, agent customer data, agent run, knowledge read/write) — the matrix is deliberate and matches the product claims, not org-wide ABAC.
Role Hierarchy
👑 Director
Full control. Can manage billing, invite any role, change roles, and delete the workspace.
- Access to all pages (Billing, Team, Approvals, Settings)
- Can invite Directors, Managers, Members, Viewers
- Can edit/delete any agent or workflow
- Can manage API keys and provider settings
- Can view audit logs and cost reports
⚙️ Manager
Team lead access. Can manage agents and workflows but cannot access billing or invite Directors.
- Access to Agents, Swarm, Ops Kanban, Chat Hub, Analytics, Staff
- Can invite Managers and Members only
- Can edit/delete agents they created
- Cannot access Billing or Team admin pages
🧑💻 Member
Standard user. Can interact with agents and participate in comms but has no admin access.
- Access to Agents, Ops Kanban, Chat Hub, Analytics (read-only), Staff
- Cannot invite new users
- Cannot create/edit agents (read-only)
- Cannot access Billing or Approvals
👁️ Viewer
Read-only observer. For external clients or stakeholders who need visibility without control.
- Access to Staff Directory and Chat Hub only
- Can view agents and messages but cannot interact
- Cannot create, edit, or delete anything
- Cannot access billing, analytics, or settings
Changing Roles
Sidebar Visibility by Role
The sidebar automatically hides pages you don't have access to:
- Director — sees all 12 pages
- Manager — hides Billing
- Member — hides Billing, Approvals, Team admin, Fuse Depot
- Viewer — sees only Staff and Chat Hub
